Phishing: How to Spot It and Report It

Overview
A phishing message presents an innocent-looking but dangerous request to share information, open a file, or run a program. The message may appear urgent or subtly enticing, but the goal is the same — to make money from your information, accounts, or computer for cybercriminals.
How can you avoid being phished?
A 2009 study found that 45% of people who were directed to a fake website via a phishing scam entered their account password. These people were fooled by the fake message and fooled by the fake website! Learn these two skills for all emails and websites to avoid the dangers of phishing:
Step 1: Check Before Acting on Unexpected Email Requests
Whenever you receive an unexpected email request, especially one that is urgent or enticing, use common sense to evaluate the message:
- If it seems suspicious, just delete it!
- If it seems likely to be real (or you can't decide), please double-check with the sender through verified contact details to confirm it!
Remember: Let your common sense guide you in determining whether a message seems suspicious or real when you receive an unexpected email request, then act accordingly.
Step 2: Check Before Entering Your Password
Whenever you need to enter your password, don't enter your password unless the website has the following:
- Encryption: The web address must show HTTPS or the lock icon.
- Matching Domain: The web address should match the organization's domain.
Remember: Do these two quick checks every time before you enter a password, just like you always quickly check your mirrors before changing lanes on the road.
Should I forward a phishing email?
No. Generally, we want you to delete phishing messages. Please do not forward them. Forwarding has many problems:
- Forwarding spreads a potentially dangerous message.
- Forwarding does not provide enough information about the suspicious message to act on.
How do I report a phishing email?
To safely and effectively report a phishing email, you can use the Phish Alert Button (PAB): 
The Phish Alert Button lets you report emails you suspect are trying to steal your information. This button will automatically remove the suspected email from your inbox and provide the Information Security Office with a forensic copy to analyze and take action against.
Guidelines for Using the Phish Alert Button:
- DO use the Phish Alert Button to report phishing messages. ISO will be notified immediately.
- DO NOT use the PAB for reporting spam. It will not make the spam stop.
- DO NOT forward phishing emails.
Frequently Asked Questions
See Also
- Security Training
- Security Blogs
- Pepperdine Email
- Pepperdine Spam Filter
- Departmental Mass Email Tips



